Datapanda
Ürün
Otomatik Raporlama Reels Analizi Rakip Analizi Rapor Tasarımı
Nasıl Çalışır Fiyatlandırma Blog SSS
Giriş Yap Ücretsiz Başla
Legal

Data Processing Agreement

GDPR-compliant data processing terms between DataPanda and its users.

Terms & Conditions Privacy Policy Cookie Policy Security Impressum Data Processing Agreement Data Deletion Refund Policy
Effective as of 1 June 2025

This Data Processing Agreement ("DPA") forms part of the agreement between Digimark GmbH ("DataPanda", "Processor") and you, the customer ("Controller"), and governs the processing of personal data in connection with the DataPanda service.

This DPA is incorporated into and subject to the Terms and Conditions. Capitalised terms not defined here have the meaning given in the Terms.


1. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person as defined in GDPR Article 4(1).

"Controller" means the natural or legal person that determines the purposes and means of processing personal data (i.e., you, the DataPanda customer).

"Processor" means Digimark GmbH, which processes personal data on behalf of the Controller.

"Sub-Processor" means any third party engaged by the Processor to process personal data.

"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.

2. Subject Matter and Nature of Processing

Digimark GmbH processes personal data on behalf of the Controller for the purpose of providing the DataPanda social media reporting service. The processing includes storage, analysis, and display of Instagram account data and any personal data contained within reports generated by the Controller.

3. Types of Personal Data and Data Subjects

The personal data processed may include: email addresses, Instagram account identifiers, Instagram public profile data (username, follower count, media metrics), and activity log data relating to the Controller's users. Data subjects are: the Controller (account holder), and optionally the Controller's own customers or clients whose Instagram data appears in shared reports.

4. Duration of Processing

Processing continues for the duration of the Controller's subscription to DataPanda, and thereafter for the period required to fulfil data deletion obligations as set out in the Data Deletion Policy.

5. Obligations of the Processor (Digimark GmbH)

Digimark GmbH agrees to:

  • Process personal data only on documented instructions from the Controller (including instructions set out in the Terms and this DPA)
  • Ensure persons authorised to process personal data are bound by appropriate confidentiality obligations
  • Implement appropriate technical and organisational security measures (GDPR Article 32)
  • Assist the Controller with data subject rights requests (access, erasure, portability, etc.)
  • Delete or return all personal data upon termination of the service relationship
  • Provide all information necessary to demonstrate compliance with GDPR Article 28

6. Sub-Processors

The Controller provides general authorisation for Digimark GmbH to engage sub-processors. Current sub-processors include:

Sub-ProcessorPurposeLocation
Stripe, Inc.Payment processingUSA (EU–US DPF)
Meta Platforms, Inc.Instagram API dataUSA (SCCs)
Cloud infrastructure providerDatabase & application hostingEU
Email delivery providerTransactional emailEU / USA (SCCs)

Digimark GmbH will notify the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object. Objections must be raised within 14 days of notification.

7. International Transfers

Where personal data is transferred to countries outside the EEA, Digimark GmbH ensures appropriate safeguards under GDPR Chapter V, including Standard Contractual Clauses (SCCs) or reliance on adequacy decisions.

8. Security

Digimark GmbH implements appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. See our Security Policy for details.

9. Data Breach Notification

Digimark GmbH will notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a personal data breach affecting the Controller's data, including the information required under GDPR Article 33(3) to the extent available.

10. Assistance with Data Subject Rights

Digimark GmbH will assist the Controller in responding to data subject rights requests by providing appropriate technical and organisational measures, insofar as this is possible given the nature of the processing.

11. Audit Rights

Digimark GmbH will make available all information necessary to demonstrate compliance with GDPR Article 28 and allow for audits conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and confidentiality obligations.

12. Governing Law

This DPA is governed by the laws of the Federal Republic of Germany.


📧 DPA inquiries: hello@digimarkstudio.com

Datapanda

Instagram verilerini anlamlı raporlara dönüştür. Ajanslar ve markalar için.

Ürün

Özellikler Fiyatlandırma Nasıl Çalışır FAQ

Şirket

Hakkımızda Blog İletişim Impressum

Yasal

Kullanım Şartları Gizlilik Politikası Çerez Politikası Veri Silme İade Politikası
Secure payments powered by Payment methods
© 2026 Datapanda.io | Instagram Reporting Tool. All Rights Reserved.
Meta Business API ortağı